// 3 ZERO-DAY · 6 CVE · 5 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Sophos researchers have uncovered Luciferus, a subscription-based service sold on underground hacking forums that generates malware via a local, unrestricted LLM. The discovery, documented in a report published September 15, 2026, signals a paradigm shift in the criminal AI market: a move away from jailbreaking mainstream models toward purpose-built, local LLMs designed without safeguards from the ground up. No more patches to bypass—just proprietary infrastructure.

Sophos researchers have identified a subscription service dubbed Luciferus, marketed on a hacking forum as a system that answers requests without moral or ethical restrictions. The discovery, documented in a report published September 15, 2026, signals a paradigm shift in the criminal AI market: the abandonment of mainstream model jailbreaks in favor of local Large Language Models designed from the ground up without safeguards. No more patches to bypass—just proprietary infrastructure.

Key Takeaways
  • Luciferus is sold on underground forums at $35, $55, and $75 per month, with a custom tier available on request
  • Sophos tested the service with a remote access trojan prompt: the system generated source code with a Russian-language explanation
  • Researchers assess with low confidence that the model is derived from Qwen, Alibaba's open-source LLM
  • A discrepancy between forum and website pricing remains unexplained; the operator's identity is unverifiable

How the Service Works and Who Buys It

The forum advertisement presents Luciferus as a stable alternative to ChatGPT and Claude jailbreaks. Three public subscription tiers are listed: Inquisitor at $35 per month, Archdevil at $55, and Prince of Darkness at $75. An additional Individual Embodiment tier offers a private model, training on customer data, and dedicated compute, with pricing negotiated on request.

However, the Luciferus website lists different names and figures: Junior at $22, Middle at $34.75, and Pro at $47.14. Sophos could not determine whether the two price lists reflect a different operator, rebranding, or a scam attempt. The seller's identity and the specific forum remain unknown.

The service is explicitly positioned as a more reliable option than jailbreak techniques. According to Sophos research, the latter lose effectiveness every time OpenAI, Anthropic, or other vendors patch their safety policies. An uncensored local LLM is not subject to this cycle: no vendor can remotely disable the model, and no update can curtail its capabilities.

The Suspect Architecture: Proprietary Model or Disguised Fine-Tuning?

The forum advertisement claims Luciferus is based on a proprietary 120-billion-parameter model. Sophos could not verify this claim, nor other promises regarding the service's performance and privacy. Researchers assess with low confidence that the system is built on Qwen, the family of open-source models developed by Alibaba, likely through fine-tuning, custom system prompts, or orchestration layers.

The distinction is not academic. As Sophos researchers note in a quote from the report: "Proprietary model claims can be misleading, as many of the services are likely based on fine-tuned open-source models, custom system prompts, or orchestration layers rather than entirely new foundation models. Training a genuinely novel LLM requires significant expertise, data, and computing resources." The "proprietary model" rhetoric serves to build credibility in the criminal market, but the technical barrier to replicating the service remains relatively low.

This mechanism has direct implications for proliferation. If Luciferus can be presented as a sophisticated solution today, it can be replicated, forked, or surpassed tomorrow by competitors with an identical technical setup. Competition shifts from possession of technical rarities to speed of commercialization.

The Sophos Test: Malware Generation on Demand

Researchers purchased the Junior tier and subjected the system to a direct prompt: the creation of a remote access trojan in Python. The response included a Russian-language explanation and complete source code. Sophos did not execute or verify the generated code. It is therefore impossible to determine whether the payload is functional, contains deliberate or accidental errors, or represents a concrete operational threat.

The significant element is not the code quality, but the total absence of filters. The system did not refuse the request, did not apply ethical warnings, and did not ask for defensive contextualization. This frictionless availability is the product being sold: not technical sophistication, but immediate readiness.

Context: From WormGPT to MessiahGPT, Criminal AI Commercializes

Luciferus is not isolated. An August 2026 Trellix report documents parallel services: MessiahGPT, positioned as a tool without ethical constraints; APEX AI, with nation-state-grade attack planning capabilities; and Metamorphic Crypter. MessiahGPT was also cited by Accenture and Google Cloud at Black Hat 2026 for its ability to generate exploits, payloads, proof-of-concepts, and malware.

"Traditionally, hacking required a deep, manual understanding of how network defenses interact with an exploit. You had to chain vulnerabilities yourself, which required a high level of specialized human knowledge" — Jambul Tologonov, Trellix

The same Trellix source adds: "Someone who wouldn't know where to begin in a pen test can now get a prioritized attack plan that mirrors APT-grade tradecraft." The skill threshold for offensive operations is structurally lowering, expanding the pool of active threat actors.

A previous service, WormGPT, suffered a user database breach in February 2026 that exposed approximately 19,000 accounts. The incident demonstrates that criminal AI services carry the same operational risks as any digital platform: customer data theft, user identification, and potential law enforcement collaboration.

A study conducted from January to July 2025 shows that 52.5% of threads on criminal forums mentioning legitimate AI products referenced ChatGPT, while WormGPT appeared in 26% of threads dedicated to criminal AI tools. The persistence of these services over time, despite short lifespans and security risks, indicates structural demand rather than occasional experimentation.

Market Trajectory: Why Jailbreaks Are Losing

The economic logic shifting the market from jailbreaks to proprietary services is straightforward. Jailbreaks are dependent on the platforms they exploit: when OpenAI or Anthropic update their alignment systems, the technique becomes obsolete. Operators must reinvest time in researching new prompts, new injection techniques, new bypasses. Uncensored local models eliminate this uncertainty.

As Sophos researchers report: "Luciferus appears to be a more stable option that relies on an uncensored local LLM instead of jailbreaking a mainstream LLM provider." Stability becomes a marketing feature in the criminal sector, just as in the legitimate one. The monthly subscription guarantees continuous access, implicit updates, and technical support. The business model replicates legitimate software-as-a-service, with the difference that the product is designed to evade any control.

This shift has consequences for defenders. Monitoring abuse of OpenAI or Anthropic APIs, while still necessary, becomes insufficient. The threat migrates toward distributed infrastructure, self-hosted models, and bulletproof hosting networks. The indicator of compromise is no longer a suspended API key, but a local server with a dedicated GPU.

Why It Matters

The emergence of Luciferus documents a transition from temporary workaround to permanent capability in cybercrime. Jailbreaks were tactics; subscription services are strategies. The difference lies in the asset's durability and the operation's scalability.

For enterprises, the implication is that defenses based on vendor patch speed lose part of their logical efficacy. There is no vendor to patch when the adversary's model is autonomous. For defenders, the monitoring horizon widens: not just mainstream AI platforms and their APIs, but marketplaces for local models, Telegram distribution channels, and underground forums with seller reputation systems.

The dossier does not specify corrective measures or detection techniques applicable to services like Luciferus. The actual number of subscribers, the service's current operational status, and relationships with other services cited in the Trellix report are not documented. The nature of data used for potential custom training in the Individual Embodiment tier remains unknown.

FAQ

Is the code generated by Luciferus verified as functional?

No. Sophos published the code received but did not execute or analyze it for efficacy. The experiment demonstrates the absence of filters, not the quality of the payload.

Why are the forum and website prices different?

The discrepancy is documented but unexplained. It may reflect a different operator, rebranding, an update error, or a scam attempt. Sophos could not resolve the anomaly.

Is Luciferus linked to WormGPT or MessiahGPT?

No evidence in the dossier links Luciferus to other cited services. The names appear in separate market trend contexts, without documented infrastructural overlap.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. helpnetsecurity.com
  2. oodaloop.com
  3. xhack.io
  4. cybersecuritydive.com
  5. securityweek.com
  6. unit42.paloaltonetworks.com